Capfin India

Privacy Policy

How We Collect, Process, and Protect Your Personal Data

Capfin India Limited

CIN: L74999PN1992PLC243323| BSE: 539198

RBI Registered NBFC (Non-Systemically Important, Non-Deposit Taking, Base Layer)

Effective Date: July, 2026

This Privacy Policy is issued by Capfin India Limited, an RBI-registered Non-Banking Financial Company. As an NBFC, our data processing activities are governed not only by the Digital Personal Data Protection
Act, 2023 (DPDPA) but also by the RBI KYC Master Directions, 2016, the Prevention of Money Laundering Act, 2002, SEBI Regulations, and applicable RBI circulars. Where RBI/SEBI obligations impose stricter
requirements than the DPDPA, those obligations shall prevail.

1. Identity of the Data Fiduciary

Capfin India Limited (“Capfin India”, “the Company”, “we”, “our”, or “us”) is the Data Fiduciary within the meaning of the Digital Personal Data Protection Act, 2023 (“DPDPA”) in respect of personal data collected and processed through this Website (www.capfinindia.in). Our details are:

  • Registered Name: Capfin India Limited
  • CIN: L74999PN1992PLC243323
  • BSE Scrip Code: 539198
  • RBI Registration: Non-Deposit Taking, Non-Systemically Important.
  • Registered Office: 6th Floor, VB Capitol Building, Range Hills Road, Opp. Hotel Symphony, Bhoslenagar, Shivajinagar, Pune – 411007, Maharashtra, India
  • Privacy / Compliance Contact: compliance@capfinindia.in
  • Managing Director: Mr. Abhishek Narbaria

2. Legal Framework

This Privacy Policy is published in compliance with the following laws, regulations, and directions, all as amended from time to time:

  • The Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Digital Personal Data Protection Rules, 2025 (once notified and effective);
  • The Information Technology Act, 2000 (“IT Act”) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), to the extent not superseded by the DPDPA;
  • The RBI Master Direction – Know Your Customer (KYC) Direction, 2016 (updated from time to time), issued under the Banking Regulation Act and RBI Act;
  • The Prevention of Money Laundering Act, 2002 (“PMLA”) and the Prevention of Money Laundering (Maintenance of Records) Rules, 2005;
  • The Reserve Bank of India (Non-Banking Financial Company – Scale Based Regulation) Directions, 2023;
  • The SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015;
  • The Companies Act, 2013 and the rules thereunder;
  • All applicable RBI circulars, master directions, and guidelines governing NBFC operations.

Where the requirements of the DPDPA or SPDI Rules differ from RBI or PMLA obligations (particularly in relation to data retention, KYC records, and AML obligations), the more stringent requirement shall apply.

3. Personal Data We Collect


3.1 Data Provided Voluntarily by You

We collect personal data that you voluntarily provide when using the Website or engaging with the Company, including:

  • Contact details — full name, email address, telephone or mobile number, and city/state when submitting an inquiry, feedback, or contact form;
  • Investor/shareholder communications — queries relating to share transfers, dematerialisation, dividends, AGM participation, or e-voting;
  • Newsletter subscription — email address and name if you subscribe to Company updates;
  • Job application data — résumé/CV, educational qualifications, employment history, and contact information if you apply for a role with the Company.


3.2 Financial and KYC Data (for Loan/Investment Applicants) 

Where you engage with the Company in relation to a loan, investment, or any other financial service (through channels separate from this Website), we may collect and process the following categories of personal data, as required by the RBI KYC Master Directions, 2016, and the PMLA:

  • Officially Valid Documents (OVDs) for identity and address verification — Aadhaar number (as per applicable RBI guidelines), PAN card, Passport, Voter ID, Driving Licence, or any other OVD as notified by the RBI;
  • Financial information — income details, bank account information, credit history, tax identification, and other financial data required for credit assessment and KYC completion;
  • Beneficial ownership and UBO information — as required for corporate borrowers and investors under PMLA;
  • Video/in-person KYC verification data — images, video recordings, or biometric data collected during V-CIP (Video-Based Customer Identification Process) as permitted by RBI;
  • Transaction data — details of loan disbursements, repayments, interest, and investment transactions. Note on Aadhaar: Collection and use of Aadhaar data is subject to the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and the applicable regulations of the UIDAI. Capfin India Limited collects and uses Aadhaar data only in the manner and to the extent expressly permitted by applicable law and RBI directions.


3.3 Data Collected Automatically from Website Use

When you visit the Website, the following technical data is collected automatically:

  • Log data — IP address, browser type and version, operating system, referring URL, pages visited, time and date of visit, and session duration;
  • Device information — device type, operating system version, screen resolution, and unique device identifiers;
  • Cookie and tracking data — data collected through session cookies, functional cookies, analytics cookies, and similar technologies (see Section 8).

4. Purposes and Legal Bases for Processing 


We process your personal data for the following specific purposes, under the indicated legal bases:


4.1 Website Inquiries and General Communication Purpose:
To respond to queries, contact requests, and feedback submitted through the Website. Legal Basis: Consent (DPDPA Section 6) / Legitimate interest.

4.2 Investor Relations and Statutory Disclosures Purpose:
To provide investor and shareholder services, including distributing meeting notices, financial results, voting facilities, and annual reports. Legal Basis: Legal obligation under SEBI LODR, Companies Act, 2013, and applicable RBI regulations.

4.3 KYC Verification and AML Compliance (Lending/Investment Services) Purpose:
To verify the identity and address of borrowers and investors and to comply with AML/CFT obligations under the PMLA and RBI KYC Master Directions, 2016. Legal Basis: Legal obligation (RBI KYC Master Directions, PMLA, DPDPA Section 7(b)).

4.4 Credit Assessment and Loan Processing Purpose:
To assess creditworthiness, process loan applications, and execute lending agreements. Legal Basis: Performance of contract / Legal obligation.

4.5 Regulatory Reporting Purpose:
To file regulatory returns and reports with RBI, SEBI, BSE, MCA, FIU-IND, and other governmental or regulatory bodies, as required by applicable law. Legal Basis: Legal obligation.

4.6 Website Security and Fraud Prevention Purpose:
To monitor, detect, prevent, and investigate fraud, security incidents, and misuse of the Website. Legal Basis: Legitimate interest / Legal obligation.

4.7 Analytics and Website Improvement Purpose:
To analyse website usage patterns and improve the Website’s performance and content. Legal Basis: Legitimate interest (using anonymised or aggregated data where possible).

4.8 Legal Proceedings and Dispute Resolution Purpose:
To establish, exercise, or defend legal claims, and to comply with court orders, regulatory directions, or legal process. Legal Basis: Legal obligation / Legitimate interest.

5. Sensitive Personal Data and Financial Data


As an NBFC, Capfin India Limited processes categories of personal data that are treated as sensitive under the SPDI Rules, 2011 and/or constitute sensitive financial personal data for purposes of the DPDPA, including:


  • Financial data (bank account details, income information, tax identification, credit history);
  • Official identity documents (Aadhaar, PAN, Passport);
  • Biometric data collected during V-CIP (processed only to the extent permitted by applicable law);
  • Any other data classified as sensitive under the DPDPA rules once notified.

Such data is collected only to the extent strictly necessary for the regulated purpose for which it is collected, is subject to enhanced security controls, and is not shared with any party other than as required by applicable RBI, PMLA, SEBI, or other statutory obligations.

6. Disclosure and Sharing of Personal Data


6.1 Regulatory and Governmental Authorities
We are legally obligated to share personal data — including KYC documents, transaction data, and beneficial ownership information — with the following authorities when required by law:

  • Reserve Bank of India (RBI) — in connection with supervisory inspections, regulatory filings, and NBFC compliance returns;
  • Financial Intelligence Unit – India (FIU-IND) — for mandatory Suspicious Transaction Reports (STRs) and Cash Transaction Reports (CTRs) under the PMLA;
  • Securities and Exchange Board of India (SEBI), BSE Limited, and other stock exchanges — for listing compliance and disclosure obligations;
  • Ministry of Corporate Affairs (MCA) — for company law filings;
  • Income Tax Department — for TDS filings, Form 26Q, and other tax obligations;
  • Courts, tribunals, and law enforcement agencies — pursuant to valid legal process, court orders, or regulatory directions;
  • Any other authority as required under applicable law.

6.2 Service Providers (Data Processors)
We engage third-party service providers who process personal data on our behalf as Data Processors under the DPDPA, including:

  • Website hosting and IT infrastructure providers;
  • Registrar and Share Transfer Agent — Indus Shareshree Private Limited (formerly Indus Portfolio Private Limited) — for share-related investor services;
  • KYC verification and V-CIP technology providers, as permitted by the RBI;
  • Credit bureaus — such as CIBIL, Equifax, Experian, and CRIF High Mark — for credit information as authorised under the Credit Information Companies (Regulation) Act, 2005;
  • Email communication, analytics, and digital infrastructure providers.


All Data Processors are bound by contractual obligations consistent with the DPDPA and applicable law to process data only on our documented instructions and to maintain appropriate security.

6.3 No Sale or Unauthorised Sharing
Capfin India Limited does not sell, rent, trade, or otherwise commercially transfer your personal data to any third party for their independent marketing or commercial purposes.

7. Data Retention

We retain personal data for the periods required by applicable law, regulation, and business necessity. The following minimum retention periods apply:

  • KYC documents and records of customers / borrowers: 5 (five) years from the date of cessation of the business relationship, or such longer period as required by the PMLA (Rule 3 of the PMLA Maintenance of Records Rules) or the RBI KYC Master Directions — whichever is greater;
  • AML/STR transaction records: 10 (ten) years as required under the PMLA;
  • Loan account and credit records: 8 (eight) years from the date of final settlement or closure of the loan account, or as required by RBI directions;
  • Investor relations and shareholder communication records: 8 (eight) years from the date of the relevant corporate event, or as required by the Companies Act, 2013, or SEBI LODR;
  • Website contact/inquiry data: 3 (three) years from the date of your last interaction with us, unless a longer period is required by applicable law;
  • Website log data and technical records: 2 (two) years, or shorter if technically impractical;
  • Employee/recruitment records: duration of employment plus applicable statutory post-employment period; or 1 (one) year from closure of application if unsuccessful.


Upon expiry of the applicable retention period, personal data will be securely deleted or irreversibly anonymised.

8. Cookies and Tracking Technologies
The Website uses cookies and similar tracking technologies. A cookie is a small text file placed on your browser or device when you access the Website.

8.1 Categories of Cookies

  • Strictly Necessary Cookies: Required for the Website to function; cannot be disabled. No personally identifiable information is stored. Retention: session only.
  • Functional Cookies: Allow the Website to remember your preferences, such as language settings. Retention: up to 12 months.
  • Analytics Cookies (e.g., Google Analytics): Help us understand how users interact with the Website. Data is aggregated and anonymised where possible. Retention: up to 24 months.
  • Security Cookies: Used to detect and prevent fraudulent access and to support authentication. Retention: session / up to 30 days.

8.2 Managing Cookies

You may control or withdraw cookie consent through your browser settings. Disabling strictly necessary cookies may impair the functionality of the Website. For further information on cookies, visit www.allaboutcookies.org. We will seek your consent for non-essential cookies in accordance with the requirements of the DPDPA rules, once notified.


9. Your Rights as a Data Principal 

Under the DPDPA and applicable law, you have the following rights in respect of your personal data processed by Capfin India Limited:


  • Right to Access (Section 11, DPDPA): You may request a summary of the personal data processed by us, the processing activities conducted, and information about the third parties with whom your data has been shared.
  • Right to Correction and Erasure (Section 12, DPDPA): You may request correction of inaccurate or incomplete data, and deletion of data that is no longer necessary for the processing purpose, subject to applicable legal retention obligations (including PMLA, RBI KYC, and SEBI requirements).
  • Right to Withdraw Consent (Section 13, DPDPA): Where processing is based on your consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
  • Note: Withdrawal of consent does not affect our right to process data pursuant to legal obligations (RBI, PMLA, SEBI).
  • Right to Grievance Redressal (Section 13(3), DPDPA): You have the right to have data-related grievances addressed in a timely manner (see Section 12 below).
  • Right to Nominate (Section 14, DPDPA): You may nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity.


Important: Your right to erasure and other DPDPA rights are subject to legal obligations under the PMLA, RBI KYC Master Directions, Companies Act, 2013, and SEBI LODR that require us to retain certain personal data for prescribed minimum periods regardless of your withdrawal of consent or erasure request.

10. Data Security

Capfin India Limited implements industry-appropriate administrative, technical, and organisational security measures to protect your personal data from unauthorised access, disclosure, alteration, loss, or destruction. These measures include:

  • Encryption of data in transit using SSL/TLS protocols;
  • Role-based access controls and multi-factor authentication for systems accessing personal data;
  • Regular security audits, penetration testing, and vulnerability assessments;
  • Contractual security and confidentiality obligations imposed on all Data Processors;
  • Secure storage of KYC and financial records in compliance with RBI guidelines on data localisation and record keeping.


In the event of a personal data breach affecting your data, Capfin India Limited will notify the Data Protection Board of India within the timelines prescribed under the DPDPA. Where required by applicable law or where the breach poses significant risk to you, we will also notify you as the affected Data Principal, with information regarding the nature of the breach and remedial measures taken.

11. Data Localisation

In accordance with applicable RBI guidelines on data localisation applicable to payment system operators and financial entities, and to the extent applicable to NBFCs, Capfin India Limited ensures that data relating to Indian customers and transactions is stored on servers/systems located within India. Any cross-border transfer of personal data is conducted only to countries, regions, or organisations identified by the Central Government under the DPDPA as meeting adequate data protection standards, or where such transfer is otherwise permitted under applicable law. Appropriate contractual safeguards (including standard contractual clauses where applicable) are implemented for all international data transfers.

12. Children’s Data

The Website is not intended for use by individuals under the age of eighteen (18) years. Capfin India Limited does not knowingly collect personal data from minors. As required under Section 9 of the DPDPA, where we become aware that personal data of a minor has been collected, we will take prompt steps to delete such data. We will not process any data of a child without verifiable parental or guardian consent where such consent is required under the DPDPA. Our Website and services do not track or behaviourally advertise to children.

13. Grievance Redressal and Data Protection Contact

For any complaint, query, or request relating to this Privacy Policy or the processing of your personal data, please contact: 


Grievance Officer / Compliance Officer
Capfin India Limited
6th Floor, VB Capitol Building, Range Hills Road,
Opp. Hotel Symphony, Bhoslenagar, Shivajinagar,
Pune, Maharashtra – 411007, India
Email: compliance@capfinindia.in
Website: www.capfinindia.in

We will endeavour to respond to all data protection grievances within thirty (30) days of receipt, as required under the DPDPA. If you are not satisfied with our response, you may approach the Data Protection Board of India (once constituted and operational) in accordance with the provisions of the DPDPA.

14. Changes to This Privacy Policy

Capfin India Limited reserves the right to amend or update this Privacy Policy at any time to reflect changes in applicable law, regulatory requirements (including new RBI circulars, DPDPA rules, or SEBI directions), or our data processing practices. The revised Policy will be published on the Website with an updated effective date. Where required by applicable law (including the DPDPA), we will seek fresh consent or provide advance notice of material changes. Your continued use of the Website following publication of any updated Policy constitutes your acceptance of the revised terms.



15. Governing Law

This Privacy Policy is governed by and shall be construed in accordance with the laws of India, including the DPDPA, IT Act, PMLA, RBI Act, Companies Act, 2013, and all applicable regulations. Any dispute arising under or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Pune, Maharashtra, India.

Contact Details:
Capfin India Limited
6th Floor, VB Capitol Building, Range Hills Road,
Opp. Hotel Symphony, Bhoslenagar, Shivajinagar,
Pune, Maharashtra – 411007, India
Email: compliance@capfinindia.in
Website: www.capfinindia.in

Scroll to Top